<?php

namespace App\Http\Controllers\Home;
use App\Home\wishwall;
use Illuminate\Http\Request;
use App\Http\Requests;
use App\Http\Controllers\Controller;

class WishwallController extends Controller
{
     public function index(){
         $notes = '';
         $left = '';
         $top = '';
         $zindex = '';
         $wish = new wishwall();
         $query = $wish->orderBy('id','desc')->limit(50)->get();
         // $query = M('wishing_wall')->query("select * from sm_wishing_wall order by id desc limit 0, 50");
	foreach($query as $k=>$row){
		 list($left, $top, $zindex) = explode('|', $row['xyz']);
		 $time = strtotime($row['addtime']);

		$notes .= "<dl class='paper a" . $row['color'] . "'  style='left:" . $left . "px;top:" . $top . "px;z-index:" . $zindex . "'data-id=" . $row['id'] . ">
		<dt>
		<span class='username'>" . $row['name'] . "</span>
		<span class='num'>" . $row['id'] . "</span>
		</dt>
		<dd class='content'>" . $row['content'] . "</dd>
		<dd class='bottom'>
		<span class='time'>" . $wish->tranTime($time) . "</span>
		<a class='close' href='javascript:void(0);'></a>
		</dd>
		</dl>";
		}
		return view('Home\wish\index',['notes'=>$notes]);
     }
     public function note(){
     	return view('Home\wish\add_note');
     }
    public function ajaxs(){
    	$act = htmlspecialchars($_GET['act']);
    	$wish = new wishwall();
		if ($act == 'update_position') {
		    if (!is_numeric($_GET['id']) || !is_numeric($_GET['x']) || !is_numeric($_GET['y']) || !is_numeric($_GET['z']))
		        die("0");

		    $id = intval($_GET['id']);
		    $x = intval($_GET['x']);
		    $y = intval($_GET['y']);
		    $z = intval($_GET['z']);
			$position->xyz=$x . "|" . $y . "|" . $z;
			$wish->where('id='.$id)->save();
		//	M('wishing_wall')->query("UPDATE sm_wishing_wall SET xyz='" . $x . "|" . $y . "|" . $z . "' WHERE id=" . $id);
		//  mysql_query("UPDATE wishing_wall SET xyz='" . $x . "|" . $y . "|" . $z . "' WHERE id=" . $id);

		    echo "1";
		}else if ($act == 'delete') {
			if($_SESSION['mg_id'] !=1){
				echo "0";
			}else{
			$id = I('get.id');
		//  $id = intval($_GET['id']);sm_wishing_wall
		    $wish->where('id='.$id)->delete();
		//  D('wishing_wall')->query("delete from sm_wishing_wall where id = ". $id);
		    echo "1";
			}
		} else if ($act == 'add') {
		    $left = intval($_POST['left']);
		    $top = intval($_POST['top']);
		    $txt = stripslashes(trim($_POST['content']));
		    $txt = htmlspecialchars($txt, ENT_QUOTES);
		//  $txt = mysql_real_escape_string(strip_tags($txt), $link); //过滤HTML标签，并转义特殊字符
		     $txt = strip_tags($txt); //过滤HTML标签，并转义特殊字符
		    if (strlen($txt) < 1 || strlen($txt) > 100) {
		        echo '内容长度为1~100字符之间';
		        exit;
		    }

		    $user = stripslashes(trim($_POST['user']));
		    $user = htmlspecialchars($user, ENT_QUOTES);
		    $user = strip_tags($user);
		//  $user = mysql_real_escape_string(strip_tags($user), $link);
		    if (strlen($user) < 2 || strlen($user) > 30) {
		        echo '姓名长度为2~10字符之间';
		        exit;
		    }
		    $color_id = intval($_POST['color_id']);
		    if ($color_id < 0 or $color_id > 5) {
		        $color_id = rand(1, 5);
		    }
		    $time = date('Y-m-d H:i:s');
		    $zIndex = $_POST['zIndex'];
		    $xyz = '' . $left . '|' . $top . '|' . $zIndex;
			$data = array('content'=>$txt,'name'=>$user,'color'=>$color_id,'xyz'=>$xyz,'addtime'=>$time);
			$query = $wish->add($data);
		//  $query = D('wishing_wall')->query("insert into sm_wishing_wall(content,name,color,xyz,addtime)values('$txt','$user','$color_id','$xyz','$time')");
		//	show_bug($query);

		    if ($query) {
		    	echo $query;
		//  	each(strip_tags($query));
		//      echo mysql_insert_id($link);
		    } else {
		        echo '出错了！';
		    }
		}
		    	
		    }
}
